Beware of JADEPUFFER, the world's first AI ransomware agent
JADEPUFFER is different because this AI agent can make decisions and also carry out attacks independently.
Jakarta (ANTARA) - Cybersecurity firm Kaspersky has warned the public to be wary of JADEPUFFER, the world’s first artificial intelligence (AI) ransomware agent, which now marks a significant turning point in cyber threats.
In the findings of Kaspersky’s Global Research and Analysis Team (GReAT), AI in cyber attacks typically plays a role in assisting human operators, but JADEPUFFER is different because this AI agent can make decisions and also carry out attacks independently.
“JADEPUFFER also demonstrates an unprecedented level of autonomy. This shows that AI agents are now capable of making independent decisions throughout the attack process, effectively replicating the reasoning of an experienced human attacker without direct supervision,” said Ye Jin, Principal Security Researcher at Kaspersky GReAT, in a statement received in Jakarta on Friday.
The AI ransomware agent, according to GReAT’s findings, is not only capable of carrying out ordinary attacks, but also evaluates when its attack fails. In a short time, it corrects itself so that its task is fulfilled.
JADEPUFFER is the first evidence that AI-powered cyber threats are now increasingly real, with analysis, adaptation, and execution capabilities on par with human capacity.
In addition to JADEPUFFER, GReAT found that there is indeed an increase in the use of agent-based AI in cyber attacks.
Ye Jin explained in detail, citing the example of ChatGPhish, a cyber attack that uses an indirect prompt injection technique that alters the trusted AI web summarisation feature (such as ChatGPT).
In this attack, cybercriminals hide malicious instructions within web pages and trick users into asking the AI assistant to summarise the content.
The AI then unknowingly forwards the inserted malicious instructions or links, making it an unwitting part of the attack.
Because the malicious content is presented through a trusted AI interface, users tend to consider it safe and click on malicious links or follow risky instructions.
At the same time, such attacks are difficult to detect by traditional security tools, as they appear to be legitimate interactions between users and AI services, rather than conventional cyber attacks.
Malicious AI agents also eliminate the need for technical knowledge to launch cyber attacks.
This was proven with the discovery of VoidLink, an AI-based and cloud-native malware framework, in January 2026.
To avoid the dangers of cyber attacks by AI agents that continue to evolve, Ye Jin shared several tips that the public, particularly business owners who are vulnerable to such cyber attacks, can follow.
The first is to implement proactive digital system defence. System owners must have a proactive defence response using AI-based threat hunting, so that hidden threats can be more easily discovered before they surface.
Next is to implement a zero trust architecture. When this approach is adopted, it means the digital system truly verifies every access request strictly.
The zero trust architecture approach is always effective in eliminating the risk of gaps forming within internal networks.
The third tip is systematic defence. Building a systematic defence means providing protection not only at endpoints, but also within networks, applications, and data.
Finally, because the cyber attacks being fought are created by AI, using AI again to counter them is inevitable.
By using large-scale models and dual-use AI technology, a system can improve its detection and response capabilities against AI-based attacks.
“When attackers can leverage AI to automate decision-making and accelerate every stage of an attack, defenders must respond with an equal level of intelligence,” said Ye Jin.
He further stated, “Cybersecurity solutions enriched with continuously updated threat intelligence are no longer merely a competitive advantage, but a crucial necessity to stay one step ahead of rapidly evolving threats.”